Trust & Security

We hold public data to a public standard. Here is exactly where we stand today — not where we hope to be.

Current commitments

  • Data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • US-region hosting only
  • Tenant isolation enforced at the database (Row-Level Security on every tenant-scoped table)
  • Every state change on the audit record
  • Zero advertising and zero individual data sales, ever
  • No product analytics and no third-party tracking scripts — the Service ships none
  • AI works in the background as tools under your control — drafts and summaries are reviewable before anything leaves
  • Provider-agnostic AI architecture — never locked to a single model vendor
  • Three residency tiers: managed cloud today; on-prem and client-held-key with pilot deployment
  • Regular automated backups with point-in-time recovery
  • Principle of least privilege for all internal access
RoadmapSOC 2 Type 1 audit targeted within 12 months of launch. We’ll update this page as we progress.

Subprocessors

ProviderPurposeRegion
SupabaseDatabase, auth, storageUS
VercelApplication hosting & CDNUS
AnthropicAI generation (provider-agnostic; swappable)US
StripePayments & billingUS
SentryError monitoringUS

These are the only third parties that process customer data today.

Not yet in use

The Service does not send email today, so no email provider handles your data. When we turn transactional email on we plan to use Resend (US-region), and we will move it into the table above before it processes anything.

Procurement resources

Documents your purchasing team may need. (Placeholder links pending final legal review.)

Insurance: E&O and cyber liability coverage in place (carriers confirmed at contracting). Security researchers: see /.well-known/security.txt.